This study conceptualizes digital infrastructure (DI) as a socio-technical design space in which sustainability is governed by infrastructure rather than being assessed post hoc through environmental, social and governance (ESG) reporting. In addition, sustainability is treated as a property of design-compliance that can be embedded, enforced and verified in DI.
A multi-stage systematic review and realist synthesis are conducted on peer-reviewed publications since 2016. Following Preferred Reporting Items for Systematic reviews and Meta-Analyses (PRISMA) technique, the survey focuses on the literatures with one sustainability mechanism and controllable and verifiable assurance artifacts in DI. Reflexive thematic analysis is combined with realist context–mechanism–outcome (CMO) analysis to integrate mechanism-by-design patterns in five non-overlapping layers of DI.
Mechanism-by-design configurations are classified into four layers, i.e. (1) observability and assurance as the verification layer, (2) carbon- and energy-based objectives embedded in site reliability engineering (SRE) at service layer, (3) energy-aware workload placement and autoscaling at the orchestration layer and (4) policy-as-code gates in CI/CD pipelines. Design-compliance is fully satisfied when comparators, assurance artifacts and measurable key performance indicators (KPIs) co-locate at the same locus of DI. The effectiveness of DI depends on regulatory maturity, telemetry granularity, deployment topology and governance routines.
The study advances the study in digital transformation and sustainability in the sense that (1) the sustainability is conceptualized as a cybernetic control property in DI and (2) design-compliance outcomes are introduced as verifiable governance at the infrastructure level.
1. Introduction
Digital infrastructure (DI) is not only a technical backbone but also a socio-technical system to integrate operational processes and human governance for enhanced sustainability (Pereda, Willcox, Candela, Sanchez, & Murrieta-Flores, 2025; Bi, Mikkola, Devpalli, & Luo, 2025; Bi, Mikkola, Ip, Yung, & Luo, 2025). However, most organizations evaluate sustainability externally based on environmental, social and governance (ESG) indicators (Bi, 2025; Bi & Zhang, 2021). These evaluations are outcome-oriented, and the corresponding practices to enhance sustainability are constrained in terms of responsiveness. This tendency generates a paradox (Annesi, Battaglia, Ceglia, & Mercuri, 2025; Chopra, Senadheera et al., 2024). While ESG indicators proliferate, a digital system is designed to generate and manage in an unsustainable manner (Andersen et al., 2021; Liu, Osterrieder, Misheva, Koenigstein, & Baals, 2023; Tan, Hashim, & Zheng, 2025). There is a growing demand to shift from governance-by-evaluation toward governance-by-infrastructure. The latter is implemented by embedding sustainability principles into system architecture, standards and control mechanisms of a digital system (Castro, Fernandez, & Colsa, 2021; Huang, Liu, Xiong, & Liu, 2025).
The rationale of adopting governance-by-infrastructure is that sustainability should be evaluated in system operation rather than be assessed as a post-hoc goal; since ESG indicators are introduced to promote compliance and symbolic signaling (Saini, Singh, Kataria, & Singh, 2025) and efficiency-driven lock-ins may lead to frequent and unsustainable routines (Huang et al., 2025). In contrast, regenerative principles by governance-by-infrastructure (Lange et al., 2022) take into the consideration of the sustainability criteria (e.g. energy proportionality, carbon footprints and ethical stewardships) in system operation. These transfers sustainability from a managerial aspiration to a systemic design.
However, several technological hurdles have yet been addressed satisfactorily to embed sustainability evaluations in system operation (Lei, Sellers, Luo, Cao, & Bi, 2024; Xu, Li, & Bi, 2024; Zhang et al., 2023). The first is the standardization of carbon or energy indicators at service levels. Without clear thresholds for acceptable resource use, energy consumptions by AI, blockchain and data-center are unconstrained (De Pascale, Faccilongo, Riefolo, Romagno, & Silvestri, 2023; Santarius et al., 2023). The second is the lack of policy-as-code mechanisms to apply sustainability principles and tackle ethical concerns (Chopra, Agrawal, Sharma, Kallmuenzer, & Vasa, 2024; Chopra, Senadheera et al., 2024; Saini et al., 2025). In other words, sustainability norms are not transformable to executable rules and the compliances must be oversighted and enforced manually. The third one is that few sustainability gates are introduced in Continuous Integration and Deployment (CI/CD) pipelines (Hojnik, Kustec, Zalokar, & Ruzzier, 2025; Huang et al., 2025) to evaluate sustainability as a design property. This review focuses on existing works on development of DI, and the concept of DI is elaborated as below.
Digital infrastructure (DI) is a socio-technical system integrating technology, human operations and organizational processes to digitalize a system's functions.
DI is defined to encompass system architecture, control logic and operational routines and embed sustainability principles in digitized operations of system. This definition excludes higher-order constructs such as organizational and dynamic capabilities and ESG indicators at the enterprise-level; note that these constructs reflect the outcomes rather than the properties of an infrastructure itself. This review focuses on technological, procedural and governance mechanisms within digital infrastructure (Florek-Paszkowska & Ujwary-Gil, 2025; Pauliuk, Koslowski, Madhu, Schulte, & Kilchert, 2022; Saini et al., 2025), and it leads to two main innovation: (1) DI is conceptualized as a design space in the socio-technical system theory with the purpose of co-evolving technologies and social institutions and assessing and pursuing sustainability in system operation (Florek-Paszkowska & Ujwary-Gil, 2025; Castro et al., 2021). (2) Sustainability is reframed and shifted from a normative aspiration into cybernetic logics (e.g. AI, IoT, blockchain and digital twins) to automate compliance mechanisms (Chen, Despeisse, & Johansson, 2020; Liao, 2024). Furthermore, context–mechanism–outcome (CMO) variations are synthesized and identified to explain the implementation of embedded controls. For instance, strong regulatory systems amplify positive effects of externally oriented digital mechanisms; internal digitalization without governance guardrails the risks of efficiency lock-ins (Huang et al., 2025).
This survey is highly motivated to seek the answers to the following three research questions (RQ).
What sustainability mechanisms-by-design exist across the distinct layers of DI?
It emerges from fragmented and dispersed studies regarding how sustainability mechanisms are allocated across the layers of DI. Despite that existing framework such as the DT Service Cascade and the 5C architecture involve technology, network, data, process and human-operations layers (Chen et al., 2020; Pauliuk et al., 2022), these layers are not well-integrated to instantiate mechanisms-by-design collectively. The instantiations of sustainability-oriented interventions such as energy-aware scheduling (Bi & Wang, 2012) and IoT-enabled monitoring (Bi, Jin, Maropoulos, Zhang, & Wang, 2023) remain conceptually isolated and lack the systematic organization within a unified analytical structure.
How control and assurance systems interact to institutionalize continuous verification and compliance within DI operations?
It relates to a comprehensive understanding of how controls, gates and assurance artifacts are embedded in the lifecycle of DI from design to deployment, operation and finally to assurance. Although life-cycle assessment, blockchain traceability, digital-twin validation and real-time AI auditing provide partial solutions (De Silva, Gunarathne, & Kumar, 2025; Pauliuk et al., 2022; Ugrinov, Ćoćkalo, Bakator, & Stanisavljev, 2025), they are isolated applications rather than interlinked mechanisms.
Which recurring CMO configurations explain when and why embedded controls succeed or fail in achieving design compliance?
Recurring contextual variations are corresponded to the performance of embedded mechanisms. Empirical studies indicate that similar digital innovations yield divergent outcomes depending on regulatory maturity, sectoral structure and organizational resources (Huang et al., 2025; Isensee, Teuteberg, Griese, & Topi, 2020). Patterns such as efficiency lock-in and rebound effects demonstrate that design compliance is not universal but context-dependent.
2. Definition of DI
In this section, the concept of DI is discussed in a socio-technical framework, and cybernetic governance is introduced as operational logic to embed sustainability as verifiable design property of a digital system.
2.1 DI as a socio-technical space (STS)
In a socio-technical space (STS), DI can be understood as a multi-layered design space in which technical architectures, human operations and institutional norms are digitized, embedded, co-evolved for enhanced sustainability. The STS theory emphasizes that technologies are inseparable from social systems that design, operate and govern them. Therefore, modelling sustainable digitalization must disaggregate an infrastructure into a set of coherent subsystems to distinguish controls and coordination (Chen et al., 2020; Pauliuk et al., 2022). To this end, DI is proposed to have five non-overlapping layers: (1) Networks, (2) Compute/Orchestration, (3) Storage/Data, (4) Processes/Pipelines (CI/CD, IaC, MLOps) and (5) Human Operations. Each layer specifies the locus where governance-by-infrastructure can occur. The proposed layered structure delineates analytical boundaries by excluding higher-order spheres such as downstream applications, user-facing services and organizational culture or strategy business and social layers (Isensee et al., 2020; Pauliuk et al., 2022; Poopunsri, Puriwat, & Hoonsopon, 2024). By focusing on these layers, sustainability is examined as an interaction of technology and people rather than as an outcome of system operations.
The network layer provides a physical and virtual environment to connect smart things. This layer is controlled by software-defined networking (SDN) and energy-aware routing to optimize bandwidth and reduce power consumption (Chen et al., 2020; Liao, Pan, & Zhang, 2023). The Compute/Orchestration layer governs resource scheduling and workload optimization by edge computing (EC), admission controllers and supervisory configuration systems (Chen et al., 2020). The storage/data layer is managed by policy-as-code rules to ensure integrity and authenticity of stored data (De Silva et al., 2025). The processes/pipelines layer integrates operational intelligence such as CI/CD sustainability gates, predictive-maintenance analytics and automated life cycle assessment (LCA) to support system's operations (Pauliuk et al., 2022; Ugrinov et al., 2025). The human operations layer anchors the socio-technical dimension. It equips the interfaces of operational teams and site reliability engineering (SRE) staff to monitor, audit and escalate sustainability compliance (Saini et al., 2025).
2.2 Cybernetic governance of DI for sustainable-by-design
Cybernetic governance provides operational logic by which sustainability is assessed continuously to sustain the properties of DI. Sustainability assessment is conceptualized as a self-regulating function in the socio-technical fabric, and it is utilized in a closed-loop system to oversee and improve infrastructure for enhanced sustainability. The enablers in a closed loop consist of setpoints (policies/SLOs), sensors (observability/telemetry), comparators (gates/controllers) and effectors (automated or manual actions), and these enablers transform normative sustainability principles into measurable, verifiable and adaptive controls (Chen et al., 2020; De Silva et al., 2025; Florek-Paszkowska & Ujwary-Gil, 2025). For example, 5C architecture of a cyber-physical system supports Connection, Conversion, Cyber, Cognition and Configuration to coordinate the system (Chen et al., 2020). Cybernetic governance aligns technological intelligence with institutional oversight and pursues sustainability objectives such as energy proportionality, carbon efficiency and data integrity.
In a cybernetic logic, design-compliance outcomes measure the conformity to sustainability-by-design principles. Unlike using external ESG indicators that are evaluated after implementation, The outcomes by sustainability-by-design evaluate the compliances in a system's operation stage. Typical sustainability-by-design tools include gate pass/fail verification, the adherence to SLOs (e.g. carbon intensity, privacy latency) and the policy-as-code conformances (De Silva et al., 2025). Moreover, the technologies such as smart things in IoT, AI-driven predictive analytics and blockchain technologies enhance the reliability and traceability of these compliances and assure the precision, security and verifiability of environmental data.
3. Research methodology
The scope of our survey is peer-reviewed journal articles in English from 2016 to present. 2016 is set as the starting year due to the presences of cloud-native controls and policy-as-code methods such as Kubernetes, SRE, operational SLOs. 2016 is also the time to implement the Paris Agreement and UN SDGs that reflects a broader shift o sustainability assessment from ex-post reports into operational controls.
The search strategy aims to maximize recalls and preserve the quality of relevant articles. The searched databases include Scopus, Web of Science Core Collection, IEEE Xplore, ACM Digital Library and Google Scholar. IEEE/ACM databases are used to count the numbers of recalls and cross-checking, and selected articles must be Scopus-indexed. Appendix Search Keywords provide searching criteria for sustainability and DI-related articles, respectively. The searching outcomes are exported in BibTeX, merged and cleaned using the attributes of DOIs, titles and years. The following five queries have been presented:
sustainability constructs × digital-transformation constructs,
climate/green/carbon/net-zero × digital-transformation constructs,
circular-economy × digital-transformation constructs,
a consolidated sustainability block × digital-transformation constructs, and
the consolidated block with database-specific token handling (e.g. quoted vs unquoted ESG/SDG terms).
The operations in different databases are harmonized in quotation, capitalization and Boolean precedence.
The eligibility of a peer-reviewed journal article is determined based on its relevance to Sustainable-by-Design DT, i.e. whether or not sustainability principles are evaluated and taken into account in the system lifecycle. Moreover, only the studies that relate to five-layer DI are selected, and the minimum relevance is measured by two criteria below:
At least one sustainability mechanism is embedded in DI as a design constraint. The mechanisms of interest include policy-as-code, carbon/energy/privacy SLOs, data-minimization or storage-lifecycle controls, admission/runtime controllers, energy-aware scheduling and observability.
At least one control/gate type is used to enforce the sustainability mechanism. The types of control/gate include pre-commit hook, CI/CD gate, admission controller, SLO/SLA threshold and various assurance artifacts used to verify compliances such as logs, dashboards, policy or configuration files, lineage/audit records, model/data cards and configuration-drift reports.
The screening process is conducted at two stages by following the guide of PRISMA 2020; Page et al. (2021): (1) titles/abstracts are screened against predefined criteria at the first stage, (2) full texts are assessed based on the criteria for minimum relevance at the second stage. After a short calibration on a pilot subset, three co-authors have screened the databases independently; while a consensus protocol is made to resolve a disagreement based on the rule of the majority (e.g. 2/3). Accordingly, the rationales are debriefed and recorded in the log of the structured decision-making process. Generative-AI tools (ChatGPT-5 Thinking, Gemini 2.5) are used as an auxiliary triage to flag records that need a review in depth. Figure 1 shows the flowchart of PRISMA. It reports the counts of identified, deduplicated, screened and full-text assessed articles in corresponding steps. Exclusion criteria are outcome-only studies, organizational-capability works without a DI control locus, application-layer–only analyses, insufficient DI evidence and inaccessible texts. Table 1 shows the details of the final corpus with n = 40 records.
4. Multi-stage analytical framework
A template is defined to extract the following information from a selected article: (1) the primary execution layer and secondary dependencies, (2) the by-design control mechanism, (3) the enforcement gate, (4) the assurance artifact and its assurance locus, (5) the design-compliance KPI including gate pass/fail, SLO adherence, policy conformance, audit completeness, and (6) the strengths on details, artifacts and DI-locus clarity. To support causal interpretation and auditability, the captured information also includes CMO memos, adjudication checks toward mechanism, gate/assurance, DI, outcome, eligibility and quality flags.
The taxonomy of DI serves as an a priori scaffold. Each article is mapped to one or more layers of DI by identifying a control locus, where the mechanism is applied, an assurance locus, where compliance is checked. Cross-layer cases specify a single primary execution layer and listed secondary dependencies. A framework is extended when the following four conditions are met: (1) the pattern has recurred in at least 3 articles, (2) the mechanism is operationalized as a design control, e.g. policy-as-code, SLO, admission/runtime rule, (3) at least one assurance artifact is present, e.g. logs, policies, lineage/audit and (4) the category is non-redundant with the existing taxonomy. The template is applied in all 40 papers to calibrate interpretations. All refinements and decisions are recorded in a codebook-evolution table to ensure a replicable bridge from reported mechanisms to DI layers.
4.1 Reflexive thematic analysis
An abductive stance is adopted to iterate between record-level extractions and a bounded a priori DI taxonomy and thus to identify themes of mechanism-by-design embedded in DI. An analysis is proceeded in the following three passes.
Pass 1 (open coding): each record is coded for the mechanism (by-design control logic), control/gate (or SLO comparator), assurance artifact and design-compliance KPI, with analytic memos, e.g. CMO-success, CMO-failure, assurance-sparse, telemetry-granularity, capturing trigger conditions and evidence loci.
Pass 2 (constant comparison): codes are clustered into candidate themes when a stable configuration: mechanism, control/gate (or SLO comparator), assurance artifact and compliance KPI, co-occurred under a clear DI control locus. Under-represented patterns were retained with caveats when recurrence fell below the prespecified threshold.
Pass 3 (rival explanations): counter-patterns (e.g. telemetry insufficiency, ambiguous assurance locus) are examined, and evidence strength is weighted by operational detail and artifact traceability. Themes are split when they differ in control locus, assurance profile or KPI type and merged when they share a primary DI layer, near-identical control logic and substitutable assurance artifacts. Reliability is verified via double-coding and consensus adjudication, with saturation declared once no new configurations emerged. The resulting themes are reported in Section 5.
4.2 Realist CMO analysis
A realist context–mechanism–outcome (CMO) logic by Pawson and Tilley (Pawson & Tilley, 1997) is adopted to explain how embedded controls yield design-compliance under specified conditions. The unit of analysis is a record-level configuration linking the mechanism (by-design control logic), its control/gate or SLO comparator, the assurance artifact and a compliance KPI, all are anchored to the same DI control and assurance loci. We count an outcome only when ≥1 DI-level KPI, e.g. SLO adherence, policy conformance, audit/lineage completeness, bounded drift and ≥1 traceable artifact converged on that locus.
Contexts are interpreted inductively but bounded by recurring domains: regulatory/standards, deployment topology, e.g. edge density, multi-region, observability/telemetry, resources/skills and governance routines. Mechanisms include executable controls such as policy-as-code, admission/runtime controllers, energy-aware placement/scheduling and retention/minimization pipelines. Outcomes reflect the performance against defined setpoints. Rigor is maintained via iterative comparison, double-coding of a pilot subset, consensus adjudication and a versioned audit trail. Negative/rival cases, e.g. weak telemetry, ambiguous assurance, are retained when they clarify causal blockages and meet a minimum evidence bar. CMO saturation is declared once no new mechanism–control/comparator–artifact–KPI configurations present in the final tranche of coded instances. The confirmed CMOs inform the results by distinguishing success/failure bundles and indicating when embedded controls generalize across DI layers vs remain context-contingent.
4.3 Coverage and gaps in DI mechanisms
Descriptive counts are reported for five DI mechanism indicators (1) policy-as-code, (2) carbon/energy SLOs, (3) storage-lifecycle controls, (4) admission/runtime controllers and (5) observability/assurance artifacts. The counting unit is one per record and multi-labeling is permitted. A record is eligible only if anchored to a DI control locus with ≥1 control/gate (or SLO comparator) or ≥1 assurance artifact. Table 2 shows that each indicator relates to the number of relevant articles (n reported), a stricter variant requiring both a compliance KPI and a traceable assurance artifact at the same locus (n verified). Table 3 further presents evidence strength and Table 4 summarizes coverage gaps, % missing artifacts and % missing KPIs among matched rows. The keywords are pre-specified and refined from the corpus vocabulary. Ambiguous-locus rows are excluded from counts and retain only as negative cases in qualitative analysis. Across the corpus, observability/assurance artifacts and carbon/energy SLOs are most frequent, whereas storage-lifecycle and admission/runtime controllers are comparatively scarce. A meaningful share of matches lacks either artifacts or explicit KPIs, indicating assurance under-reporting (Figure 2). Keywords are pre-specified and refined from the corpus vocabulary, ambiguous-locus rows are excluded from counts and retained as negative cases.
4.4 Trustworthiness, validity and sensitivity analyses
We ensured thoroughness by verifying reflexivity, transparency and sensitivity. The experts in a multi-disciplinary team make brief positionality statements and anticipated points of disagreements, e.g. DI locus vs application layer, and disagreements are resolved by consensus. Borderline records are retained only when two independent eligibility signals are present (e.g. mechanism keyword and assurance artifact, or explicit comparator and KPI); unresolved cases are then excluded. In reflexive thematic analysis (TA), reliability is strengthened by ongoing memos, systematic constant comparison, clearly defined split/merge criteria and documentation of saturation. For realist CMO, potential threats to validity include construct drift in assurance artifacts, selection or reporting bias, limited generalizability and researcher bias. These are addressed by using keywords lists to stabilize construct definitions, search multiple databases, minimize inclusion criteria, clarify scoping statements explicitly and maintain memos to mitigate biases by researchers, respectively.
5. Empirical findings
Figure 1 shows that the screening and eligibility assessment processes lead to a final corpus of 40 articles. These articles meet the inclusion minima and are coded as 92 DI-level records with distinct mechanisms. Table 1 provides the full list of these 40 articles, and record-level counts are used in subsequent directed-count analyses. In the survey window from 2016 to present, the number of publications has been increased gradually recent years due to an increasing popularity of cloud-native controls, policy-as-code and sustainability instrumentation.
The selected articles cover various domains including public services, manufacturing, energy and logistics. This indicates the generality of DI to support embedded controls in heterogenous applications. Sectoral notes are retained in CMO memos for later interpretation. Among 92 records, frequently observed constructs are CI/CD and IaC controls, admission/runtime controllers, observability/telemetry with lineage/audit, storage-lifecycle rules and carbon/energy SLOs. These descriptors only serve as signposts, and the results emphasize how such constructs operate as by-design controls in DI. Eligibility is fundamental to infrastructure-embedded mechanisms; therefore, articles on outcome-driven or strategy-driven mechanisms are excluded. Borderline cases follow a negative-case protocol.
5.1 Counts and evidence strengths
The indicators, eligibility minima and counting rules introduced in Section 4 are adopted to analyze the coverages of five DI-mechanism indicators. Table 2 reports directed counts under the lenient rule (e.g. “n reported”) and the stricter rule (e.g. “n verified”), respectively. These correspond to a co-located design-compliance KPI and a traceable assurance artifact at the same DI locus. Table 3 classifies the same indicators by evidence strengths. Table 4 quantifies coverage gaps mentioning lacking artifacts and/or KPIs.
Table 2 shows that under the lenient rule (e.g. “n reported”), two dominate indicators are Observability/Assurance Artifacts with (57, 62.0%) and the Carbon/Energy SLOs of (33, 35.9%). Secondary indicators are Policy-as-Code (2, 2.2%) and Storage Lifecycle (1, 1.1%), ignorable indicator is for Admission/Runtime Controllers with (0, 0%). When a strict threshold is applied, the counts of applied indicators are Observability/Assurance (53, 57.6%), Carbon/Energy SLOs (27, 29.3%), Policy-as-Code (1, 1.1%), Storage Lifecycle (1, 1.1%) and Admission/Runtime (0, 0%). It is expected that the value of “n verified” is less than that of “n reported” for indicators.
Table 3 shows that that Observability/Assurance contributes the largest Strong segment; this reflects inherent generation of auditable traces (logs/dashboards/lineage/audit/drift/model/data cards) and more frequent reporting of KPI such as pass/fail, audit completeness and bounded drift. Carbon/Energy SLOs align with partial co-reporting of comparator/telemetry/effector or KPI. Policy-as-Code and Storage Lifecycle remain sparse and mostly are moderate or weak. All rows are stated after eligibility filtering.
Table 4 shows substantial missing artifacts of gap diagnostics for Policy-as-Code (23) and Carbon/Energy SLOs (22) and limited missing-KPI instances. In practice, mechanisms are often implemented without been connected to verifiable artifacts (e.g. log/policy repository, audit trail, configuration snapshot). This explains the discrepancy of the attrition between “n reported” to “n verified”, particularly for SLOs and Policy-as-Code.
5.2 Themes of mechanism-by-design
In this section, four themes of mechanism-by-design in DI are discussed and synthesized and Table 5 summarizes these themes. The attributes of a theme include (1) the elements including DI locus and lifecycle stage, (2) the comparator used to evaluate setpoints (e.g. SLO thresholds or policy-as-code gates), (3) assurance artifacts that substantiate compliance (e.g. logs, dashboards, lineage/audit), and (4) design-compliance KPIs (e.g. SLO adherence, gate pass/fail). Moreover, our discussion is extended to a concise CMO exemplar grounded in strict evidence, a contrasting failure vignette that explains illegibility, and a one-sentence micro-takeaway to determine minimum.
Theme 1: Observability/assurance in verification layer. Observability serves at a verification layer spanning CI/CD pipelines and SRE operations, closing the build, deploy, operate, audit loop. Sustainability setpoints are evaluated primarily against SLO thresholds. They are often framed by error budgets for energy/carbon and evidentiary completeness; logs, dashboards and lineage/audit traces provide the assurance trail. In some records, drift reports and model/data cards are also applied (Chen et al., 2020; Perdana & Chu, 2025). Design-compliance is evidenced by SLO adherence and audit completeness and pipeline gate pass/fail records (Perdana & Chu, 2025). In multi-region deployments, the SRE/pipeline locus is verified by dashboards and auditable entries (Perdana & Chu, 2025). As a rule, this pattern travels when SLOs are explicitly bound to sufficiently granular/coverage-rich telemetry and the assurance artifact co-locates with the comparator at the same DI locus. Otherwise, SLO/observability is mentioned without a traceable KPI or co-located artifact (Ramesohl et al., 2021).
Theme 2: Carbon/energy SLOs in SRE. Carbon/energy SLOs are implemented in SRE run-ops post-deployment; operational manuals are used to tun workloads so as to control environmental indicators toward to target ranges. Comparators are SLO thresholds and error budgets applied to operational energy/carbon metrics (e.g. carbon intensity per workload). Dashboards, SLO documents and audit trails substantiate decisions and actions (Chen et al., 2020; Huang et al., 2025). Design-compliance is indicated by SLO adherence over defined windows in some instances by error-budget consumption (Huang et al., 2025). This mechanism generalizes when setpoints specify units/thresholds, telemetry signals are bound to those setpoints and runbook-to-action links culminate in a recorded KPI. Telemetry/comparator details are incomplete, the resolutions are suggestive and unverified (Ramesohl et al., 2021).
Theme 3: Energy-aware workload placement and autoscaling. At the compute/orchestration (runtime) layer, placement controllers and auto-scalers allocate resources by considering energy consumption objectives to satisfy setpoints during real-world operations. Comparators are SLO thresholds executed by runtime controllers, and assurance is provided by telemetry logs (workload–resource–energy signals), dashboards and drift reports (Lövehagen, 2023). Design-compliance is recorded as SLO adherence and bounded drift per interval/workload. When high-granularity telemetry and sufficient edge density are present, runtime controllers maintain energy/carbon SLOs, with telemetry logs and drift reports evidencing the control loop at the orchestration locus (Lövehagen, 2023). More broadly, the approach extends to other contexts when setpoints are explicit and telemetry is reliable and granular. Where signals are sparse or thresholds unspecified, controllers operate blind and results should be treated as potential rather than enforceable (Sigurjonsson et al., 2024).
Theme 4: Policy-as-code gates for ESG controls. Policy-as-code is executed in CI/CD pipelines; it serves as a pre-commit/CI gate that blocks non-conformant builds prior to deployment. The comparator is a policy-as-code rule acting as a gate (sometimes paired with admission rules), with the assurance trail expected to include a policy repository identifier/commit hash, gate logs (pass/fail) and an audit trail (Florek-Paszkowska & Ujwary-Gil, 2025; Hojnik et al., 2025). Design-compliance is typically recorded as gate pass/fail and policy conformance per build (Hojnik et al., 2025). In operational pipelines, policy rules stop non-conformant builds, with policy repo IDs and gate pass/fail logs providing verifiable evidence at the CI/CD locus (Hojnik et al., 2025). As evidence, this mechanism generalizes when rules are codified and enforced by gates that produce traceable pass/fail records tied to a versioned policy repo. Where reports cite policies without logs or KPIs, the claims remain declarative rather than controlling (Ramesohl et al., 2021).
Across themes, design-compliance is achieved only when a co-located triad, comparator (gate/SLO), assurance artifact and KPI, closes the feedback loop at the same DI locus. The most robust bundle couples SLOs with observability, which sustains strict verification. Runtime orchestration succeeds under high-granularity telemetry and explicit setpoints, while policy-as-code gates remain architecturally critical yet empirically thin, indicating an implementation gap rather than a conceptual weakness. Section 5.3 synthesizes the cross-theme CMO configurations and specifies minimum conditions under which these embedded controls generalize across sectors and deployment topologies.
5.3 Synthesize bundles of embedded controls and research gap
Digital tools in multiple themes are synthesized as the bundles of embedded controls within a DI locus. In synthesis, “n (reported)” reflects co-occurrence, “n (verified)” shows the number of verified of comparator/gate or SLO, assurance artifact and KPIs in a locus of DI. Table 6 shows that the dominant bundle is B1 (SLOs and Observability) with n (reported) = 25 and n (verified) = 0 (drop 100%). While SLOs and observability are associated frequently, the co-location of comparator–artifact–KPI is rarely made explicitly. Other bundles are sparse in this corpus. B2 (Admission/Runtime and SLOs and Observability) shows n (reported) = 0 and n (verified) = 0, B3 (Policy-as-Code and Observability) n (reported) = 1 and n (verified) = 0 (drop 100%) and B4 (Storage Lifecycle and Observability) n (reported) = 1 and n (verified) = 0 (drop 100%).
Since “n (verified)” is 0 for all combinations in Table 6, no co-occurrence has been observed from our study. The dominant failure mode is ambiguous DI locus, multi-layer descriptions are not specified to primary execution locus, and outright artifacts or KPIs are absent. Existing studies on SLOs and observability do not explicitly co-locate the comparator, the assurance artifact and a design-compliance KPI within the same locus of operations. Few reference regulatory/standards or resources/skills, and cues for topology or telemetry depth are explicitly made.
6. Discussion and limitations
6.1 From embedded mechanisms to design-compliance
Here, the surveying results are summarized to answer three research questions on how sustainability mechanisms are embedded, enforced and verified within DI. The ultimate objective is to delineate a consistent cybernetic logic, i.e. sustainability is assessed and pursed through embedded mechanisms (mechanism-by-design), mediated by controls and gates, substantiated by assurance artifacts and expressed as design-compliance outcomes within the operational cycle.
RQ1: Typology of embedded mechanisms. Among five DI layers, four recurring mechanism types define how sustainability is instantiated technically: (1) observability and assurance systems serve at the verification layer, (2) carbon- and energy-based SLOs are used at the service layer, (3) energy-aware workload placement and autoscaling are applied at the compute-orchestration layer and (4) policy-as-code gates are embedded in CI/CD pipelines. These mechanisms translate normative sustainability principles into executable control logics that govern digital operations. Observability and SLO mechanisms dominate the corpus, appearing in more than half of all verified records (Huang et al., 2025; Perdana & Chu, 2025), while policy-as-code and storage-lifecycle enforcement are comparatively rare (De Silva et al., 2025; Hojnik et al., 2025). Overall, sustainability-by-design capability already exists within DI but is unevenly instantiated and often under-evidenced (Chen et al., 2020; Pauliuk et al., 2022).
RQ2: Interaction of controls, gates and assurance. Design-compliance emerges only when comparators (SLO thresholds or gates), assurance artifacts (logs, dashboards, lineage or audit traces) and measurable KPIs co-locate at a single DI locus. Applying this strict verification bar, all identified bundles (B1–B4) registered as near-misses. Mechanisms are reported but lacked either traceable artifacts or explicit KPIs. The most mature configuration, which is SLO and Observability, illustrates potential for continuous verification. SLO setpoints are evaluated through telemetry and confirmed through auditable records, enabling a self-closing feedback loop (Huang et al., 2025; Perdana & Chu, 2025). Where telemetry depth and locus clarity are sufficient, sustainability is enforced as a technical property. Where either is missing, compliance remains declarative, a gap particularly evident for policy-as-code mentions without gate logs or KPI traces (Hojnik et al., 2025; Ramesohl et al., 2021).
RQ3: Context–mechanism–outcome (CMO) configurations. Successful design-compliance arises under contexts of regulatory maturity, adequate telemetry coverage and defined governance routines that link setpoints to operational runbooks. In such cases, clear policies and SLOs (C) activate automated or human effectors (M) that maintain bounded drift and document conformity (O) (De Silva et al., 2025; Saini et al., 2025). Failure configurations feature ambiguous loci, weak observability or resource constraints that prevent the closure of feedback loops, particularly in edge-dense or multi-region topologies where telemetry granularity is not specified (Chen et al., 2020; Lövehagen, 2023). Regulatory alignment and organizational capability therefore mediate whether embedded controls generalize across sectors or remain local exemplars.
The above findings from RQ1 to RQ3 show that sustainability becomes verifiable only when DI-embedded mechanisms are cybernetically bound through explicit comparators, traceable assurance artifacts and measurable KPIs. When these triads converge within the same infrastructure locus, governance transitions from retrospective ESG reporting toward proactive, self-regulating design, realizing sustainability as an engineered property of DI rather than a post-hoc performance goal.
6.2 Theoretical implications
This review extends STS theory by positioning DI as an engineered governance substrate in which sustainability is not merely supported but enforced by design. Evidence across the corpus shows that observability layers, SLO-driven run-ops and policy-as-code gates couple technical control planes with organizational routines, relocating the locus of governance from external oversight to infrastructure-embedded mechanisms (Isensee et al., 2020; Perdana & Chu, 2025). The observed cross-layer coordination, linking pipelines, orchestration and human operations, transforms DI from a passive technical system into a reflexive socio-technical environment capable of shaping its own compliance practices.
From the perspective of cybernetics, the findings operationalize the classic feedback architecture in DI: setpoints (policies/SLOs), sensors (telemetry/observability), comparators (gates/controllers) and effectors (automation or human-in-the-loop). Crucially, design-compliance appears only when these functions co-locate at a single DI locus and are substantiated by a verifiable artifact and KPI. For example, SLO thresholds evaluated by dashboards and confirmed by auditable logs (Huang et al., 2025; Perdana & Chu, 2025). Where telemetry depth, comparator specificity, and assurance traceability align, the loop closes and governance becomes self-correcting. Where any element is missing (e.g. policy mentions without gate logs/KPIs), mechanisms remain declarative and compliance unverified (Hojnik et al., 2025; Ramesohl et al., 2021). This co-location criterion refines cybernetic governance from a conceptual ideal to a testable design condition in operational settings.
From a resource-based and natural-resource-based view (RBV), the study indicates that controls and assurance artifacts (e.g. versioned policy-as-code repos, lineage/audit trails, telemetry schemas, SRE runbooks) function as difficult-to-imitate infrastructural assets. Their value arises not only from code or tools but from context-specific integration with processes, roles and topology. This yields capabilities that are path-dependent, organization-embedded and defensible over time (De Silva et al., 2025; Hojnik et al., 2025). In sustainability terms, these assets enable ongoing constraint satisfaction, e.g. energy/carbon SLOs, rather than one-off performance gains, aligning with NRBV's emphasis on capabilities that reduce environmental burdens.
Theoretical contributions of our work are at two aspects: (1) in STS, DI is shown to embody cybernetic reflexivity, with human-ops explicitly acting as effectors within verifiable loops and (2) in cybernetics, verifiability (comparator, artifact and KPI at one locus) is advanced as the minimal design rule for enforceable sustainability. These implications clarify why many reported mechanisms are near-misses and specify how infrastructures must be architected to convert sustainability from a reported outcome into a property of the system by design.
6.3 Practical implications
To make proposed DI practical in sustainable manufacturing, the practical implications of a governance-by-infrastructure are discussed to translate design-compliance principles into actionable items in five layers of DI. The main enablers of DI are the co-located triad, a comparator (policy or gate), an assurance artifact and a measurable KPI that coexist within the same DI locus. Once these enablers are implemented systematically, the proposed DI allows to transform sustainability from a declarative objective into a verifiable, self-auditing process.
Network layer. Codify routing, rate-limiting and energy-efficiency policies as executable code. Enforce them through pre-deployment checks or network-admission rules and verify through flow logs and configuration snapshots. Common KPIs include energy-per-bit, packet-drop ratio and policy-conformance percentage.
Compute/orchestration layer. Define carbon- or energy-based SLOs per workload and embed admission or runtime controllers that block configurations exceeding thresholds. Scheduler logs and telemetry dashboards act as assurance artifacts. KPIs include SLO adherence and bounded drift per interval or workload.
Storage/data layer. Implement retention, minimization, encryption and localization constraints as policies, validate them through lifecycle gates in CI or automated jobs. Lineage and audit trails constitute the assurance record, with KPIs, such as deletion-on-time rate, zero PII-leak incidence and configuration-drift tolerance.
Processes/pipelines layer (CI/CD, IaC, MLOps). Maintain version-controlled policy-as-code repositories for ESG-relevant rules and deploy pre-commit or CI gates to stop non-conformant builds. Gate pass/fail logs and commit hashes provide assurance evidence, while KPIs track policy-pass rates and mean-time-to-remediation. For instance, CI-gate enforcement of policy-as-code has been demonstrated in cloud-native run-ops (Hojnik et al., 2025).
Human-ops-for-infra layer. Couple operational runbooks with SLOs so that incident responses and change requests are bounded by error-budget policies. Dashboards and audit trails verify actions, with KPIs such as error-budget consumption and audit completeness. For instance, SLO-driven SRE practices with auditable traces are documented in multi-region operations (Perdana & Chu, 2025).
Moreover, each locus should maintain (1) versioned policies referenced in gate logs, (2) telemetry signals explicitly tied to quantitative setpoints and (3) KPIs defined in operational terms (pass/fail, adherence, bounded drift). Every layer must designate an accountable assurance owner, typically within SRE or governance teams, responsible for linking runbooks to verifiable actions. When these conditions are met, comparator, artifact and KPI converge to close the feedback loop.
6.4 Summary and future research
This review shows that sustainability should be engineered and embedded into DI. It has identified systemic gaps of existing works that limit verifiable governance-by-infrastructure. Addressing these gaps calls for promising mechanisms in reproducible and auditable practice, and we anticipate that future researches are in the following four critical areas.
Future research is required to fill interrelated gaps that presently limit the realization of verifiable governance-by-infrastructure. Existing logs, lineage records, audit trails and drift reports often lack interoperable metadata and provenance structures, which constrains their integration across systems. Further studies might explore the design of minimal, machine-verifiable schemas and ontologies that facilitate cross-system aggregation, provenance validation and independent assurance. Developing a shared reference or conformance suite could also help establish consistency in artifact formats and verification practices.
Future research benefit from deeper inquiry concerns benchmarks for carbon and energy gates. Thresholds, measurement units and workload-normalized metrics remain uneven across studies and deployment contexts. Establishing a more consistent benchmarking framework, by incorporating reference workloads, boundary conditions such as region or topology and standardized test harnesses, could make it easier to compare gate performance and evaluate run-time SLO adherence in a transparent manner.
The theoretical foundation is lacked to model cross-layer orchestration and dependencies. Many control mechanisms operate in isolation without explicit awareness of upstream or downstream dependencies. Future work could aim to formalize orchestration patterns that connect CI/CD gates, runtime controllers and SRE routines through explicit dependency graphs and shared setpoints. The development of reusable design patterns may help generalize these architectures across multiple infrastructure layers.
There are numerous opportunities to advance tooling for design-compliance telemetry. Current observability stacks rarely link telemetry signals directly to policies or KPIs. Research could therefore investigate instrumentation approaches and APIs that associate telemetry with explicit setpoints, register comparator results as first-class events and produce tamper-evident artifacts automatically. Taken together, these directions may contribute to a maturity model for sustainable-by-design DI, advancing the STS conception of infrastructure as a socio-technical control system and rendering cybernetic governance progressively more interoperable, transparent and self-regulating.
6.5 Limitations of our survey
This review is subject to several limitations arising from data scope, classification precision and reporting heterogeneity. The corpus is dominated by engineering and information-systems sources, emphasizing technical mechanisms while under-representing organizational and socio-institutional dimensions. Distinguishing sustainable-by-design from outcome-oriented work required interpretive judgment, and ambiguous descriptions of mechanisms, gates or assurance loci introduce residual risk of misclassification. Evidence inconsistency further constrains synthesis. Above limitations are partially due to that fact that many research papers lacked explicit KPIs, DI-locus detail or traceable artifacts, limiting verifiability and contributing to near-miss patterns. Conceptual drift in terms such as policy-as-code, SLO and observability also reduced cross-study comparability.
7. Conclusions
This review examines how sustainability can be embedded within DI, shifting the focus from external ESG reporting to internal design-compliance outcomes. It argues that policy-as-code, gates and assurance artifacts can serve as verifiable controls, translating sustainability principles into executable governance logic. Within socio-technical and cybernetic perspectives, sustainability becomes a property of design where governance is built into infrastructure rather than applied externally. The findings extend socio-technical systems theory toward cybernetically reflexive infrastructures capable of sensing, comparing and adapting their own performance. Sustainability emerges when comparators, assurance artifacts and KPIs co-locate at a single DI locus, forming feedback loops that render compliance continuous, auditable and adaptive. This framing links technical and institutional dimensions of governance, showing how normative goals can be operationalized through embedded control logic.
In practice, architects should encode sustainability rules as code, enforce them through automated gates and ensure auditable evidence through verifiable artifacts. Regulators should likewise privilege machine-verifiable proof over self-reported claims, embedding accountability directly within the infrastructure. Future research and development should focus on shared schemas for assurance artifacts, benchmarks for carbon and energy gates, and interoperable telemetry for design-compliance. Collectively, these advances can mature sustainable-by-design digital transformation, where compliance becomes an intrinsic, transparent and continuously verifiable function of design itself.
Ethical statement
To ensure transparency and responsible use of generative AI, the authors disclose that AI tools (OpenAI ChatGPT, version GPT-5) were employed under direct author supervision to support, but not replace, human research and writing. AI assistance was used solely to enhance linguistic quality, structural clarity and methodological completeness of the manuscript. Specifically, AI was engaged to: (1) polish the entire paper to a formal academic tone, (2) help enumerate and review the theoretical foundations relevant to the study, while the final theory selection was made solely by the authors, (3) suggest best-practice outlines for drafting and structuring sections, with all substantive modifications and content development performed by humans, (4) refine or shorten selected paragraphs for conciseness, (5) assess drafted paragraphs for potential missing elements, where AI suggestions were considered but never followed automatically, (6) assist in confirming coding completeness during the synthesis stage, with all AI feedback verified manually against the original papers, (7) provide feedback on the suitability of thematic groupings, (8) review the research methodology for completeness and (9) generate Python scripts for data visualization.
All core research activities including topic formulation, methodological design, literature search, inclusion and coding of papers, thematic synthesis, discussion and interpretation, were entirely conceived and executed by the human research team. The authors used AI only as an auxiliary tool to improve precision and readability, and all AI-generated suggestions were independently reviewed and validated for accuracy and appropriateness before inclusion in the final manuscript.
The supplementary material for this article can be found online.




